Are you passionate about Application Security, Open Source Software (OSS) Security, and Vulnerability Research? We are looking for a Senior Security Consultant to join our cybersecurity team and play a key role in identifying, validating, and triaging security vulnerabilities across open-source ecosystems.
Key Responsibilities
Vulnerability Analysis & Validation
- Investigate and analyze security findings from automated vulnerability scanners.
- Distinguish genuine vulnerabilities from false positives, informational findings, and AI-generated inaccuracies.
- Perform root cause analysis and assess exploitability and business impact.
- Validate reported security issues and recommend remediation strategies.
Threat Modeling & Security Assessment
- Develop threat models for open-source repositories and applications.
- Identify attack surfaces, trust boundaries, and security risks.
- Conduct risk-based security assessments within broader application ecosystems.
- Document vulnerability classifications and triage decisions.
- Contribute to the development of high-quality datasets for AI security model training and benchmarking.
- Provide feedback to enhance automated vulnerability detection capabilities.
Required Skills
- Strong hands-on experience in Application Security, Vulnerability Research, Penetration Testing, Product Security, or Secure Software Engineering.
- Proven expertise in Open Source Software (OSS) Security Assessment and Vulnerability Analysis.
- Excellent code review, debugging, and security analysis skills in:
- C/C++
- Go
- Java
- Python
- Experience with Bash scripting or similar scripting languages is preferred.
What We're Looking For
- Deep understanding of secure coding practices and software vulnerabilities.
- Strong analytical and problem-solving skills.
- Ability to independently investigate complex security issues and communicate findings effectively.
- Passion for improving software security through research and innovation.